NoditBLOCK
A Model Context Protocol (MCP) server for AI agents to interact with blockchain data via Nodit’s Web3 Data and Node APIs. Enables LLMs to access structured, multi-chain blockchain context with zero blockchain-specific logic.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server that connects AI agents and developers to structured, context-ready blockchain data across multiple networks through Nodit's Web3 infrastructure.
[](https://opensource.org/licenses/Apache-2.0) [](https://nodejs.org/) [](https://www.typescriptlang.org/) [](https://smithery.ai/server/@noditlabs/nodit-mcp-server)
Overview
Nodit MCP Server simplifies how AI models and applications interact with blockchain ecosystems. Instead of handling complex node RPCs, raw event logs, or chain-specific data structures, developers can access normalized, multi-chain blockchain data in a format optimized for AI reasoning and decision-making.
With Nodit's MCP, you can:
- Build AI agents that query, analyze, and act on real-time blockchain data across EVM-compatible and non-EVM networks.
- Develope Web3-integrated applications without requiring specialized blockchain development expertise.
- Leverage Nodit's reliable node infrastructure, Web3 Data APIs, and GraphQL indexing services through a unified access layer.
- Easily develop with blockchain MCP in both local and remote integration, depending on your workflow needs.
Supported networks include Ethereum, Base, Optimism, Arbitrum, Polygon, Aptos, Bitcoin, Dogecoin, TRON, XRPL, GIWA(Sepolia) and more.
Table of Contents
- List of Tools
- Features
- Prerequisites
- [Running Local Nodit MCP Server](#running-local-nodit-mcp-s
57aed7f90edcOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add nodit-mcp-server --env NODIT_API_KEY=${NODIT_API_KEY} -- npx -y @noditlabs/[email protected]{
"mcpServers": {
"nodit-mcp-server": {
"command": "npx",
"args": [
"-y",
"@noditlabs/[email protected]"
],
"env": {
"NODIT_API_KEY": "${NODIT_API_KEY}"
}
}
}
}Exposed tools (8)
8 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
call_nodit_api | read | |
call_nodit_aptos_indexer_api | read | |
get_nodit_api_spec | read | |
get_nodit_aptos_indexer_api_spec | read | |
list_nodit_api_categories | read | |
list_nodit_aptos_indexer_api_query_root | read | |
list_nodit_data_apis | read | |
list_nodit_node_apis | read |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
return yaml.load(fileContents);
.gitmodules
@modelcontextprotocol/sdk, js-yaml, zod, @types/js-yaml, @types/node, typescript
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.0/install.sh | bash
Gates applied: no_behavioural_pass.
57aed7f90edcfull audit observations/trust-audit/mcp-server/noditlabs__nodit.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 57aed7f90edc | BLOCK | D | 69 | first audit |
Questions
What is the Nodit MCP server?
A Model Context Protocol (MCP) server for AI agents to interact with blockchain data via Nodit’s Web3 Data and Node APIs. Enables LLMs to access structured, multi-chain blockchain context with zero blockchain-specific logic.
What tools does Nodit expose?
8 in total: 8 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Nodit safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Nodit need?
It reads NODIT_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Nodit run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @noditlabs/nodit-mcp-server at 1.2.1.
How current is this page?
The grade is for one exact copy of the source (57aed7f90edc), read on 2026-10-09. The repository is watched and re-audited when it changes.